Latest CVE Feed
-
2.4
LOWCVE-2024-46383
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
2.4
LOWCVE-2022-31224
Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior... Read more
- Published: Sep. 12, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2024-13087
A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
2.4
LOWCVE-2024-3128
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Replify-Messenger 1.0 on Android. This issue affects some unknown processing of the file androidmanifest.xml of the component Backup File Handler. The ... Read more
Affected Products :- Published: Apr. 01, 2024
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2017-18673
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the Location service on a locked device, making it impossible for the rightful owner to find a stolen device. The Samsung ID is SVE-2017-8524 (May 2017).... Read more
Affected Products : android- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2022-33706
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.... Read more
Affected Products : samsung_gallery- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2016-11027
An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximate attacker can read notifications on the lock screen. The Samsung ID is SVE-2016-7132 (December 2016).... Read more
Affected Products : android- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2024-57375
Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) via certain deselect actions.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
2.4
LOWCVE-2024-3629
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : hl_twitter- Published: May. 15, 2024
- Modified: May. 15, 2025
-
2.4
LOWCVE-2019-19563
A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.... Read more
Affected Products : hermes- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2020-12039
Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedical menus includi... Read more
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2020-4071
In django-basic-auth-ip-whitelist before 0.3.4, a potential timing attack exists on websites where the basic authentication is used or configured, i.e. BASIC_AUTH_LOGIN and BASIC_AUTH_PASSWORD is set. Currently the string comparison between configured cre... Read more
Affected Products : django-basic-auth-ip-whitelist- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2020-1833
Honor 9X smartphones with versions earlier than 9.1.1.172(C00E170R8P1) have an improper authentication vulnerability. A logic error occurs when handling clock function, an attacker should do a series of crafted operations quickly before the phone is unloc... Read more
- Published: May. 29, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2019-8732
The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device.... Read more
Affected Products : iphone_os- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2019-4265
IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker gaining sensitive information about the device. IBM X-Force ID: 160198.... Read more
Affected Products : maximo_anywhere- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2021-25409
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.... Read more
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2020-8341
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). After resuming from S3 sleep mode in vari... Read more
Affected Products : thinkpad_t490_\(20nx\)_firmware thinkpad_t490_\(20qx\)_firmware thinkpad_t490_\(20rx\)_firmware thinkpad_t490s_\(20nx\)_firmware thinkpad_t590_\(20nx\)_firmware thinkpad_x1_carbon_\(20qx\)_firmware thinkpad_x1_yoga_\(20qx\)_firmware thinkpad_x390_\(20qx\)_firmware thinkpad_x390_\(20sx\)_firmware thinkpad_t495_drift_firmware +10 more products- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2024-3430
A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an unknown part of the file androidmanifest.xml of the component Backup File Handler. The manipulation leads to exposure of backup file to an un... Read more
Affected Products :- Published: Apr. 07, 2024
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2016-4593
The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Jul. 22, 2016
- Modified: Apr. 12, 2025
-
2.4
LOWCVE-2023-32394
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.... Read more
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024